QUESTION 271Your network contains an Active directory forest named contoso.com. The forest contains two child domains named east.contoso.com and west.contoso.com.You install an Active Directory Rights Management Services (AD RMS) cluster in each child domain.You discover that all of the users in the contoso.com forest are directed to the AD RMS cluster in east.contoso.com.You need to ensure that the users in west.contoso.com are directed to the AD RMS cluster in west.contoso.com and that the users in east.contoso.com are directed to the AD RMS cluster in east.contoso.com.What should you do?

A. Modify the Service Connection Point (SCP).B. Configure the Group Policy object (GPO) settings of the users in the west.contoso.com domain.C. Configure the Group Policy object (GPO) settings of the users in the east.contoso.com domain.D. Modify the properties of the AD RMS cluster in west.contoso.com.

Answer: BExplanation: The west.contoso.com are the ones in trouble that need to be redirected to the west.contoso.com not the east.contoso.com.

QUESTION 272Hotspot QuestionYour network contains an Active Directory domain named contoso.com.You have a failover cluster named Cluster1 that contains two nodes named Server1 and Server2. Both servers run Windows Server 2012 R2 and have the Hyper-V server role installed.You plan to create two virtual machines that will run an application named App1. App1 will store data on a virtual hard drive named App1data.vhdx. App1data.vhdx will be shared by both virtual machines.The network contains the following shared folders:– An SMB file share named Share1 that is hosted on a Scale-Out File Server. – An SMB file share named Share2 that is hosted on a standalone file server.– An NFS share named Share3 that is hosted on a standalone file server.You need to ensure that both virtual machines can use App1data.vhdx simultaneously.What should you do? To answer, select the appropriate configurations in the answer area.

Answer:

QUESTION 273Your network contains an Active Directory domain named contoso.com. The domain contains a server named Server1 that runs Windows Server 2012.Server1 is the enterprise root certification authority (CA) for contoso.com.You need to enable CA role separation on Server1.Which tool should you use?

QUESTION 274Your network contains two Web servers named Server1 and Server2. Both servers run Windows Server 2012 R2.Server1 and Server2 are nodes in a Network Load Balancing (NLB) cluster. The NLB cluster contains an application named App1 that is accessed by using the URL http://app1.contoso.com.You plan to perform maintenance on Server1.You need to ensure that all new connections to App1 are directed to Server2. The solution must not disconnect the existing connections to Server1.What should you run?

A. The Set-NlbCluster cmdletB. The Set-NlbClusterNode cmdletC. The Stop-NlbCluster cmdletD. The Stop-NlbClusterNode cmdlet

Answer: DThe Stop-NlbClusterNode cmdlet stops a node in an NLB cluster. When you use the stop the nodes in the cluster, client connections that are already in progress are interrupted. To avoid interrupting active connections, consider using the -drain parameter, which allows the node to continue servicing active connections but disables all new traffic to that node.-Drain <SwitchParameter>Drains existing traffic before stopping the cluster node. If this parameter is omitted, existing traffic will be dropped.

QUESTION 275Your network contains an Active Directory domain named contoso.com. All user accounts reside in an organizational unit (OU) named OU1. You create a Group Policy object (GPO) named GPO1. You link GPO1 to OU1. You configure the Group Policy preference of GPO1 to add a shortcut named Link1 to the desktop of each user. You discover that when a user deletes Link1, the shortcut is removed permanently from the desktop. You need to ensure that if a user deletes Link1, the shortcut is added to the desktop again. What should you do?

QUESTION 276Your network contains an Active Directory forest named contoso.com. The forest contains two sites named Main and Branch. The Main site contains 400 desktop computers and the Branch site contains 150 desktop computers. All of the desktop computers run Windows 8. In Main, the network contains a member server named Server1 that runs Windows Server 2012. You install the Windows Server Update Services server role on Server1. You need to ensure that Windows updates obtained from Windows Server Update Services (WSUS) are the same for the computers in each site. You want to achieve this goal by using the minimum amount of administrative effort. What should you do?

A. From the Update Services console, create computer groups.B. From the Update Services console, configure the Computers options.C. From the Group Policy Management console, configure the Windows Update settings.D. From the Group Policy Management console, configure the Windows Anytime Upgrade settings.E. From the Update Services console, configure the Synchronization Schedule options.

Answer: CExplanation:Create one computer group for Main site and another group for Branch site. You can deploy Windows updates by computer group.

QUESTION 277You have a server named DNS1 that runs Windows Server 2012 R2.You discover that the DNS resolution is slow when users try to access the company intranet home page by using the URL http://companyhome.You need to provide single-label name resolution for CompanyHome that is not dependent on the suffix search order.Which three cmdlets should you run? (Each correct answer presents part of the solution.Choose three.)

Answer: ABDExplanation:*The Add-DnsServerPrimaryZone cmdlet adds a specified primary zone on a Domain Name System (DNS) server.* The Add-DnsServerResourceRecordCName cmdlet adds a canonical name (CNAME) resource record to a specified Domain Name System (DNS) zone. A CNAME record allows you to use more than one resource record to refer to a single host *The Set-DnsServerGlobalNameZone cmdlet enables or disables single-label Domain Name System (DNS) queries. It also changes configuration settings for a GlobalNames zone.The GlobalNames zone supports short, easy-to-use names instead of fully qualified domain names (FQDNs) without using Windows Internet Name Service (WINS) technology. For instance, DNS can query SarahJonesDesktop instead of SarahJonesDesktop.contoso.com.

QUESTION 278Your network contains an Active Directory domain named adatum.com. You have a standard primary zone named adatum.com. You need to provide a user named User1 the ability to modify records in the zone. Other users must be prevented from modifying records in the zone. What should you do first?

A. Run the Zone Signing Wizard for the zone.B. From the properties of the zone, change the zone type.C. Run the new Delegation Wizard for the zone.D. From the properties of the zone, modify the Start Of Authority (SOA) record.

Answer: C

QUESTION 279Your network contains a single Active Directory domain named contoso.com. All domain controllers run Windows Server 2012 R2.The domain contains 400 desktop computers that run Windows 8 and 10 desktop computers that run Windows XP Service Pack 3 (SP3). All new desktop computers that are added to the domain run Windows 8.All of the desktop computers are located in an organizational unit (OU) named OU1.You create a Group Policy object (GPO) named GPO1. GPO1 contains startup script settings. You link GPO1 to OU1.You need to ensure that GPO1 is applied only to computers that run Windows XP SP3.What should you do?

A. Create and link a WML filter to GPO1B. Run the Set-GPInheritance cmdlet and specify the -target parameter.C. Run the Set-GPLink cmdlet and specify the -target parameter.D. Modify the Security settings of OU1.

Answer: AExplanation:WMI Filtering is used to get information of the system and apply the GPO on it with the condition is met. Security filtering: apply a GPO to a specific group (members of the group)

QUESTION 280Your network contains an Active Directory domain named contoso.com.Network Policy Server (NPS) is deployed to the domain.You plan to deploy Network Access Protection (NAP).You need to configure the requirements that are validated on the NPS client computers.What should you do?

QUESTION 281Your network contains an Active Directory domain named contoso.com. The domain contains a server named Server1 that runs Windows Server 2012 R2 and has the DNS Server server role installed.Server1 is configured to delete automatically the DNS records of client computers that are no longer on the network. A technician confirms that the DNS records are deleted automatically from the contoso.com zone.You discover that the contoso.com zone has many DNS records for servers that were on the network in the past, but have not connected to the network for a long time.You need to set the time stamp for all of the DNS records in the contoso.com zone.What should you do?

A. From DNS Manager, modify the Advanced settings from the properties of Server1B. From Windows PowerShell, run the Set-DnsServerResourceRecordAging cmdletC. From DNS Manager, modify the Zone Aging/Scavenging PropertiesD. From Windows PowerShell, run the Set-DnsServerZoneAging cmdlet.

Answer: D

QUESTION 282Your network contains an Active Directory domain named contoso.com. The domain contains a server named Server1 that runs Windows Server 2012 R2.You enable and configure Routing and Remote Access (RRAS) on Server1.You create a user account named User1.You need to ensure that User1 can establish VPN connections to Server1.What should you do?

A. Modify the members of the Remote Management Users group.B. Add a RADIUS client.C. Modify the Dial-in setting of User1.D. Create a connection request policy.

QUESTION 283Your network contains an Active Directory domain named contoso.com.All user accounts reside in an organizational unit (OU) named OU1. All of the users in the marketing department are members of a group named Marketing. All of the users in the human resources department are members of a group named HR.You create a Group Policy object (GPO) named GPO1. You link GPO1 to OU1.You configure the Group Policy preferences of GPO1 to add two shortcuts named Link1 and Link2 to the desktop of each user.You need to ensure that Link1 only appears on the desktop of the users in Marketing and that Link2 only appears on the desktop of the users in HR.What should you configure?

Answer: DExplanation:You can use item-level targeting to change the scope of individual preference items, so they apply only to selected users or computers. Within a single Group Policy object (GPO), you can include multiple preference items, each customized for selected users or computers and each targeted to apply settings only to the relevant users or computers.http://technet.microsoft.com/en-us/library/cc733022.aspx

QUESTION 284You have a server named Server1 that runs a Server Core Installation of Windows Server 2012 R2 Datacenter.You have a WIM file that contains the four images of Windows Server 2012 R2 as shown in the Images exhibit. (Click the Exhibit button.)

You review the installed features on Server1 as shown in the Features exhibit. (Click the Exhibit button.)

You need to install the Server Graphical Shell feature on Server1.Which two possible sources can you use to achieve this goal? (Each correct answer presents a complete solution. Choose two.)

A. Index 1B. Index 2C. Index 3D. Index 4

Answer: BDExplanation:When you install Windows Server 2012 R2 you can choose between Server Core Installation and Server with a GUI. The “Server with a GUI” option is the Windows Server 2012 R2 equivalent of the Full installation option available in Windows Server 2008 R2. The “Server Core Installation” option reduces the space required on disk, the potential attack surface, and especially the servicing requirements, so we recommend that you choose the Server Core installation unless you have a particular need for the additional user interface elements and graphical management tools that are included in the “Server with a GUI” option. For this reason, the Server Core installation is now the default. Because you can freely switch between these options at any time later, one approach might be to initially install the Server with a GUI option, use the graphical tools to configure the server, and then later switch to the Server Core Installation option. Reference: Windows Server Installation Options

QUESTION 285Your network contains an Active Directory forest named contoso.com. The forest contains two domains named contoso.com and childl.contoso.com. The domains contain three domain controllers. The domain controllers are configured as shown in the following table.

You need to ensure that the KDC support for claims, compound authentication, and kerberos armoring setting is enforced in both domains.Which two actions should you perform? (Each correct answer presents part of the solution.Choose two.)